Jul 2026: Microsoft SharePoint Server Spoofing Vulnerability
CVE-2026-54108 Published on July 14, 2026
Microsoft SharePoint Server Spoofing Vulnerability
External control of file name or path in Microsoft Office SharePoint allows an authorized attacker to perform spoofing over a network.
Weakness Type
External Control of File Name or Path
The software allows user input to control or influence paths or file names that are used in filesystem operations.
Products Associated with CVE-2026-54108
Want to know whenever a new CVE is published for Microsoft products? stack.watch will email you.
Affected Versions
Microsoft SharePoint Enterprise Server 2016:- Version 16.0.0 and below 16.0.5561.1001 is affected.
- Version 16.0.0 and below 16.0.10417.20175 is affected.
- Version 16.0.0 and below 16.0.19725.20434 is affected.